« Volver al listado

CVE-2026-68198

Estado: RecibidaAlta (8.8)—

In the Linux kernel, the following vulnerability has been resolved:

wifi: ath6kl: fix use-after-free in aggr_reset_state()

The aggr_reset_state() function uses timer_delete() (non-synchronous) for the aggregation timer before proceeding to delete TID state and before the structure is freed by callers like aggr_module_destroy().

If the timer callback (aggr_timeout) is executing when aggr_reset_state() is called, the callback will continue to access aggr_conn fields like rx_tid[] and stat[] which may be freed immediately after by kfree(aggr_info->aggr_conn) in aggr_module_destroy().

Additionally, the timer callback can re-arm itself via mod_timer() while aggr_reset_state() is running, creating a more complex race condition.

Leer descripción completaMostrar menos

Use timer_delete_sync() instead to ensure any running timer callback has completed before returning.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Red adyacente (AV:A) sin privilegios. Use-after-free en timer permite DoS (crash) o escalada de privilegios local si se explota la condición de carrera; confianza moderada por ser un defecto kernel sin PoC público.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-68198",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
              "lessThan": "a1bac650b2d6b1baab1f3e78e2e007a6e2948dde",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
              "lessThan": "2132a6db05846dd2318857d00e0c1291f9e41b29",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
              "lessThan": "17ff29cd8dbc977c97788a5f7c011ec807b58242",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
              "lessThan": "64af6534a085f49d6ed33338a19ab9cf0d0523c9",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
              "lessThan": "b5d618fd61b9069b4c0a6b487022dd3117ad5acc",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
              "lessThan": "18965470d41e69d3fc10eb62afae29d10f4cdfd1",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
              "lessThan": "a3313111b5d9046af60b370c93eec105b27380c1",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "bdcd81707973cf8aa9305337166f8ee842a050d4",
              "lessThan": "ba7debb4dd6427386862220e8335a53a4bfc235d",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/net/wireless/ath/ath6kl/txrx.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.2"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "3.2",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.266",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.217",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.184",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.151",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.103",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.42",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/net/wireless/ath/ath6kl/txrx.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-10T13:20:07.277",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/17ff29cd8dbc977c97788a5f7c011ec807b58242",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/18965470d41e69d3fc10eb62afae29d10f4cdfd1",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/2132a6db05846dd2318857d00e0c1291f9e41b29",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/64af6534a085f49d6ed33338a19ab9cf0d0523c9",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a1bac650b2d6b1baab1f3e78e2e007a6e2948dde",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a3313111b5d9046af60b370c93eec105b27380c1",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b5d618fd61b9069b4c0a6b487022dd3117ad5acc",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ba7debb4dd6427386862220e8335a53a4bfc235d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath6kl: fix use-after-free in aggr_reset_state()\n\nThe aggr_reset_state() function uses timer_delete() (non-synchronous)\nfor the aggregation timer before proceeding to delete TID state and\nbefore the structure is freed by callers like aggr_module_destroy().\n\nIf the timer callback (aggr_timeout) is executing when aggr_reset_state()\nis called, the callback will continue to access aggr_conn fields like\nrx_tid[] and stat[] which may be freed immediately after by\nkfree(aggr_info->aggr_conn) in aggr_module_destroy().\n\nAdditionally, the timer callback can re-arm itself via mod_timer() while\naggr_reset_state() is running, creating a more complex race condition.\n\nUse timer_delete_sync() instead to ensure any running timer callback\nhas completed before returning."
    }
  ],
  "lastModified": "2026-08-23T13:16:35.023",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}